Latest CVE Feed
-
8.8
HIGHCVE-2025-36633
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could arbitrarily delete local system files with SYSTEM privilege, potentially leading to local privilege escalation.... Read more
Affected Products :- Published: Jun. 13, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Authorization
-
8.4
HIGHCVE-2025-36631
In Tenable Agent versions prior to 10.8.5 on a Windows host, it was found that a non-administrative user could overwrite arbitrary local system files with log content at SYSTEM privilege.... Read more
Affected Products :- Published: Jun. 13, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-28389
Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Authentication
-
9.8
CRITICALCVE-2025-28388
OpenC3 COSMOS v6.0.0 was discovered to contain hardcoded credentials for the Service Account.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-28386
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
9.1
CRITICALCVE-2025-28384
An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS 6.0.0 allows attackers to execute a directory traversal.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-28382
An issue in the openc3-api/tables endpoint of OpenC3 COSMOS 6.0.0 allows attackers to execute a directory traversal.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2025-28381
A credential leak in OpenC3 COSMOS v6.0.0 allows attackers to access service credentials as environment variables stored in all containers.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2025-28380
A cross-site scripting (XSS) vulnerability in OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the URL parameter.... Read more
Affected Products : cosmos- Published: Jun. 13, 2025
- Modified: Jun. 17, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-46096
Directory Traversal vulnerability in solon v.3.1.2 allows a remote attacker to conduct XSS attacks via the solon-faas-luffy component... Read more
Affected Products : solon- Published: Jun. 13, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2025-46060
Buffer Overflow vulnerability in TOTOLINK N600R v4.3.0cu.7866_B2022506 allows a remote attacker to execute arbitrary code via the UPLOAD_FILENAME component... Read more
- Published: Jun. 13, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-45988
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the cm... Read more
Affected Products : bl-wr9000_firmware bl-wr9000 bl-ac1900_firmware bl-ac1900 bl-ac2100_az3_firmware bl-ac2100_az3 bl-x10_ac8_firmware bl-x10_ac8 bl-lte300_firmware bl-lte300 +8 more products- Published: Jun. 13, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45987
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain multiple command injection vulnerabilities via the dn... Read more
Affected Products : bl-wr9000_firmware bl-wr9000 bl-ac2100_az3_firmware bl-ac2100_az3 bl-lte300_firmware bl-lte300 bl-f1200_at1_firmware bl-f1200_at1 bl-x26_ac8_firmware bl-x26_ac8 +4 more products- Published: Jun. 13, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45986
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 werediscovered to contain a command injection vulnerability via the mac paramete... Read more
Affected Products : bl-wr9000_firmware bl-wr9000 bl-ac2100_az3_firmware bl-ac2100_az3 bl-x10_ac8_firmware bl-x10_ac8 bl-lte300_firmware bl-lte300 bl-f1200_at1_firmware bl-f1200_at1 +6 more products- Published: Jun. 13, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45985
Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26_AC8 v1.2.8, BLAC450M_AE4 v4.0.0 and BL-X26_DA3 v1.2.7 were discovered to contain a command injection vulnerability via the bs_SetSSIDH... Read more
Affected Products : bl-wr9000_firmware bl-wr9000 bl-ac2100_az3_firmware bl-ac2100_az3 bl-x10_ac8_firmware bl-x10_ac8 bl-lte300_firmware bl-lte300 bl-f1200_at1_firmware bl-f1200_at1 +6 more products- Published: Jun. 13, 2025
- Modified: Jul. 10, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-45984
Blink routers BL-WR9000 V2.4.9, BL-AC1900 V1.0.2, BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 V1.0.5, BL-LTE300 V1.2.3, BL-F1200_AT1 V1.0.0, BL-X26_AC8 V1.2.8, BLAC450M_AE4 V4.0.0 and BL-X26_DA3 V1.2.7 were discovered to contain a command injection vulnerability via... Read more
Affected Products : bl-wr9000_firmware bl-wr9000 bl-ac1900_firmware bl-ac1900 bl-ac2100_az3_firmware bl-ac2100_az3 bl-x10_ac8_firmware bl-x10_ac8 bl-lte300_firmware bl-lte300 +8 more products- Published: Jun. 13, 2025
- Modified: Jul. 10, 2025
-
8.6
HIGHCVE-2025-49468
A SQL injection vulnerability in No Boss Calendar component before 5.0.7 for Joomla was discovered. The vulnerability allows remote authenticated users to execute arbitrary SQL commands via the id_module parameter.... Read more
Affected Products :- Published: Jun. 13, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Injection
-
10.0
CRITICALCVE-2025-29902
Remote code execution that allows unauthorized users to execute arbitrary code on the server machine.... Read more
Affected Products :- Published: Jun. 13, 2025
- Modified: Jun. 16, 2025
-
2.5
LOWCVE-2025-48825
RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may allow an attacker who can conduct a man-in-the-middle attack to eavesdrop upgrade requests and execute a malicious DLL with custom code.... Read more
Affected Products :- Published: Jun. 13, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-46783
Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is running by tampering with specific files used on the produ... Read more
Affected Products :- Published: Jun. 13, 2025
- Modified: Jun. 16, 2025
- Vuln Type: Path Traversal